Ok, this was solved: the MDM profile in question had our VPN under one name, and the WCF under another ("Foo" and "Foo 1"), and this apparently made it not work. I really need to get familiar with MDM deployment, sigh.
Topic:
App & System Services
SubTopic:
Networking
Tags: